Security scanners only check what's in the package. Malicious actors are exploiting that narrow view with mutable external links that change after approval—and a single fake skill already reached 26,000 agents before anyone noticed.

Only 17.7% of the catalog is popular enough to be graded, 1 in 32 graded skills is unsafe, and the...

AIR says its fake AI skill passed scanner checks by using a mutable external link, exposing a blind spot in agent skill vetting.